top of page

The KEV Race, July to September: Which Vendors Let Attackers Into the Soft Center, and How Many Licks It Took

Writer: Patrick Duggan
Patrick Duggan
7 hours ago
6 min read

Security is layered. An enterprise is a Tootsie Pop: a hard candy shell of firewalls and VPN gateways, then the applications people use, then the consoles that run everything, and finally the soft center where identity, privilege and the money live. Attackers do not want the shell. They want the center, and the question every defender should ask about a new KEV entry is how many licks it takes to get there.


So we ran a race. Every vendor gets the same car: the same scoring applied to the 100 entries CISA added to its Known Exploited Vulnerabilities catalog in July, August and September 2026. One race per month, IROC style, where the "winner" is the vendor whose bugs let attackers deepest, fastest, with the fewest steps. Best losers, in other words.



How the race is scored


We put every KEV entry on a layer. The shell is edge gear: VPN and remote-access appliances, firewalls, load balancers, routers, mail gateways, and browsers and phones as the user's own front door. Next come exposed applications: content management, collaboration, file sharing, ticketing, printing. Then the control plane: management consoles, SD-WAN orchestrators, remote-management tools, build and artifact systems, workflow engines, AI gateways and backup. The center is identity and directory services, operating-system privilege, hypervisor management and crown-jewel business data.


A lick is one KEV bug in the attacker's path. A vendor scores a one-lick finish when a single bug that needs no login lands an attacker in the control plane or the center. A two-lick finish is two bugs in the same product that chain, which is the toxic-combination pattern we track: a flaw that gives access without credentials, plus a flaw that runs code but supposedly requires credentials.


Points, all the same for everyone: 10 per layer reached, plus 30 for a one-lick path or 15 for a two-lick chain, 15 if CISA flags known ransomware use, 10 if a public proof of concept existed on or before the day CISA listed the bug, and 3 for each additional KEV entry that month. Season points go 25, 18, 15, 12 and down by finishing position.


Two honesty rules. A bug counts as needing no login only when CISA's own description says so. Arista's two VeloCloud entries say only "a remote attacker", and the VMware vCenter entry says "network access", so neither counts as unauthenticated here. And chains count only inside one product. Paths that cross products or vendors appear separately as the worst stack of the month, with every step named.





July: Oracle takes the flag, Cisco and Fortinet on the podium


CISA added 26 entries. Oracle won with one: CVE-2026-46817 in E-Business Suite, which CISA says lets an unauthenticated attacker with network access take over Oracle Payments. One lick, straight to the money, and a public proof of concept existed 14 days before the listing.


Cisco finished second with CVE-2026-20316 in Firewall Management Center: a hard-coded password that lets an unauthenticated attacker log in, with known ransomware use. The console that runs your firewalls is control plane, not shell.


Fortinet was third. Its two FortiSandbox command injections, CVE-2026-25089 and CVE-2026-39808, need no login, and public exploit code existed 36 and 27 days before CISA listed them. Check Point's SmartConsole token leak, CVE-2026-16232, came fourth. SonicWall's SMA1000 pair, a server-side request forgery and a code injection, both flagged for ransomware, finished sixth because the code injection needs an administrator, which keeps the chain at the shell.


The worst stack of July went SonicWall SMA1000 for the door, Cisco FMC for the brain, and Oracle E-Business Suite for the center. But the center did not need the stack: Oracle was one lick on its own.



August: JetBrains wins, and N-able patches its patch


CISA added 31. JetBrains won with CVE-2026-63077 in TeamCity, an unauthenticated remote code execution through the agent polling protocol, with known ransomware use. Whoever owns the build server owns everything the build server signs and ships.


N-able was second. CVE-2026-18556 is an authentication bypass in N-central, the remote-management console managed-service providers use to run their customers' machines. CVE-2026-18577, listed the next day, is the same bypass because the first fix was incomplete. One lick into a tool built to touch every endpoint.


Microsoft finished third on volume, four entries, without a one-lick or same-product chain to the center on the record. PaperCut and TrueConf tied behind it with genuine two-lick chains. CISA's own description of the PaperCut pair says each "can be chained" with the other.


The worst stack went PaperCut for the door, TeamCity for the brain, and VMware vCenter for the center. The vCenter bug, CVE-2026-59310, runs code and carries a ransomware flag, but CISA does not say whether it needs a login. Two licks, both ransomware-flagged.



September: Cisco wins the month and the season


CISA added 43, its busiest month of the three. Cisco won with four entries. Identity Services Engine, CVE-2026-76460, lets an unauthenticated attacker bypass the management interface on the system that decides who gets on the network. That is the center in one lick. Alongside it, a Firewall Management Center authentication bypass, CVE-2026-20079, had public exploit code 32 days before listing, and Catalyst SD-WAN Manager, CVE-2026-76504, hands an unauthenticated attacker admin privileges.


Kestra was second: unauthenticated creation and execution of workflows, CVE-2026-49869, with public exploit code 64 days before CISA listed it. JFrog was third with three Artifactory entries, one of which, CVE-2026-82329, gives an unauthenticated caller administrative privileges in the default configuration. N-able came back for fourth with a pre-authentication code injection, CVE-2026-86218, tied with BerriAI's LiteLLM, where an arbitrary bearer token opens an authenticated session on the gateway that holds your AI keys.


The worst stack went Citrix NetScaler for the door, through an authentication bypass with public exploit code seven days early, then Cisco FMC and SD-WAN Manager for the brain, and Cisco ISE for the center. Again the center was reachable directly. One lick.





Season standings


Cisco takes the season with 43 points: second in July and first in September. It and Oracle are the only two vendors with a one-lick path to the center in our window. N-able is second with 30, from finishes in August and September. Oracle and JetBrains each won a month for 25. Kestra and Check Point have 18.



What the race says about time to exploit


The listing is not the starting gun. Of the July entries with a public proof of concept in our harvester, 9 of 17 had one by the day CISA listed the bug. In August it was 9 of 15. In September it was 7 of 21. The median gap between public code and listing went from one day before listing in July to the same day in August to one day after in September. The earliest cases are not close calls: Starlette's request smuggling had public code 97 days before listing, Tomcat's 85, Kestra's 64, Langflow's 58. Our harvester timestamps are when we indexed someone else's public code, so the real gaps are, if anything, longer.


The pattern across all three months is the same. The bugs that win are not edge bugs. They are control-plane bugs that need no login: firewall managers, SD-WAN orchestrators, remote-management consoles, build servers, workflow engines, artifact stores and AI gateways. Patch lists still lean on the shell because that is where the scanners make noise. The center is reached through the consoles nobody exposes on purpose.



What to do with this


Rank your patching by depth, not just severity. An unauthenticated bug in anything that manages other things beats a higher-scored bug in a single appliance. Find out where your consoles are reachable from: firewall managers, SD-WAN orchestrators, N-central, ScreenConnect, TeamCity, Artifactory, Kestra, LiteLLM, ISE. If the answer is "the internet" or "the whole internal network", that is the soft center showing. Do not wait for KEV: in July and August more than half the listed bugs with public code already had it on listing day.



Our layer assignments


So anyone can dispute a placing: shell includes SonicWall SMA1000, Cisco IOS, ASA and FTD, and Secure Email Gateway, FortiOS and Fortinet's multi-product heap overflow, Citrix NetScaler, Progress LoadMaster, Microsoft IKE, MikroTik RouterOS, Zyxel switches, F5 BIG-IP APM, Check Point gateway products, DD-WRT, KNX, Chromium, Pixel, Apple's multi-product entry and macOS Screen Sharing. Control plane includes Cisco FMC and SD-WAN Manager, Check Point SmartConsole, FortiSandbox, Arista VeloCloud Orchestrator, N-able N-central, ConnectWise ScreenConnect, JFrog Artifactory, JetBrains TeamCity, Gitea, GitLab, Kestra, Ray, MLflow, LiteLLM, Acronis Backup and WSO2's API control plane. The center includes Microsoft ADFS, Windows and SQL Server, Cisco ISE, the Linux kernel, Red Hat libuser and ABRT, VMware vCenter and Oracle E-Business Suite. Everything else is an exposed application. Moving Oracle E-Business Suite from the center to the application layer would cost Oracle the July win and hand it to Cisco. We kept it in the center because the bug takes over payments.


Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.




Every indicator in this post is in the feed. Free.

1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.



Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=kev-race-jul-sep-2026-who-let-attackers-into-the-center-licks



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page